Balancer's Annual Security Incident Review: Total Losses Exceed $21 Million Due to Flash Loans, Front-End Hijacking, and Cross-Protocol Vulnerabilities
BlockBeats News, November 3rd, the DeFi protocol Balancer is currently under attack, with losses exceeding $1.166 billion across multiple chains, and the attack on Balancer is still ongoing. According to on-chain AI analysis tool CoinBob (@CoinbobAI_bot) summary, Balancer's historical security events are as follows:
· June 2020 Flash Loan Attack: An attacker exploited the compatibility issue between deflationary tokens (STA/STONK) and the Balancer smart contract, draining the liquidity pool by repeatedly calling swapExactAmountIn, ultimately profiting $523,600.
· August 2023 V2 Pool Vulnerability: The Balancer V2 pool was subjected to multiple flash loan attacks due to a code vulnerability, resulting in a total loss of $2.1 million. The team urgently paused the affected pool and advised users to withdraw, but funds that were not withdrawn in time were still exploited.
· September 2023 Frontend Hijacking Attack: A hacker seized control of the Balancer frontend through BGP/DNS hijacking, tricking users into authorizing a malicious contract, resulting in a loss of $238,000. On-chain sleuth ZachXBT traced the fund flow to address 0x645710Af050E26bB96e295bdfB75B4a878088d7E.
· 2023 Euler Incident Fallout: Due to a vulnerability in Euler Finance, the Balancer bbeUSD pool suffered a $11.9 million loss, representing 65% of the pool's TVL. The team took protective measures to restrict liquidity withdrawals.
· 2024 Velocore Attack Affiliation: The Velocore exploit involving a Balancer-style CPMM pool resulted in a $6.8 million loss. Balancer's technical architecture was indirectly implicated due to cross-protocol integration.
You may also like

Trading Everything, Never Closing: RWA Perpetual Contracts (Part 1)

Morning News | Nscale completes $2 billion Series C funding; 20 millionth Bitcoin has been mined; Polymarket will launch S&P 500 binary options products

Dialogue between Vitalik and Suji: Why have decentralized social products failed?

Trading Never Sleeps: On-Chain, Crude Oil, and Leverage

On-chain Yield Panorama: The Evolution from Interest-bearing Stablecoins to Crypto Credit Products

RootData announced the integration with OpenClaw, and these gameplay features have gone viral

Key Market Intelligence on March 9th, how much did you miss out on?

a16z: After AI Superpowers, Where to Next for Humanity?

Why Does Oil Go Up When Bitcoin Goes Down?

Decoding 112,000 Polymarket Addresses: The Top 1% Making Money Are Doing These Five Things

AAVE founder issues a warning: DeFi must never become the exit liquidity for Wall Street private credit
How To Create A Frequency So Strong It Makes Reality Obey You
The first-ever WEEX AI Hackathon has concluded, with 10 winners emerging from over 200 global teams. Beyond its $1.8 million prize pool, the event marked a milestone—proving that the future of AI trading belongs to accessible, AI-powered innovation.

The cryptocurrency industry has waited for five and a half years, and what they got is half a ticket

The trend of Ethena reveals what information about the cryptocurrency market

I've been in the crypto industry for five and a half years, and all I got was half a ticket.

Crude Oil Surges 25%, Hyperliquid Unfolds On-Chain Showdown

$20 Billion Valuation, Is Kalshi Engaging in an Arms Race with Polymarket?
